Package Health

xiuchuan/ecc

The repository has one star and no security policy. It includes a README and release notes, but the declared MIT license differs from the EPL-1.0 license file.

Latest 1.0.1PackagistPackagist

40%

Total Score

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

64

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

Only two releases were published, both in November 2021, with no releases in the last 12 months. This long period without a new release is strong evidence of abandonment risk.

Licensecaution

The artifact includes a license file, but it identifies EPL-1.0 while the manifest declares MIT. The package is licensed, yet the mismatch creates avoidable legal uncertainty.

Repo package mentioncaution

The repository name matches the package, but its README does not mention the package name. That makes package ownership less clearly documented and is a minor transparency concern.

Repo popularitycaution

The linked repository has 1 star and 2 forks, showing a very small user and contributor footprint. Low popularity is supporting evidence rather than a verdict, but it provides little backing against the maintenance concerns.

Security policycaution

The repository has no security policy. For a package implementing cryptographic algorithms, this weakens vulnerability-reporting transparency.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Wang Yi

Direct Dependencies

DependencyLast ReleaseScore
fgrosse/phpasn1
Version ^2.0

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform